Goutil is a collection of miscellaneous functionality for the go language. In versions prior to 0.6.0 when users use fsutil.Unzip to unzip zip files from a malicious attacker, they may be vulnerable to path traversal. This vulnerability is known as a ZipSlip. This issue has been fixed in version 0.6.0, users are advised to upgrade. There are no known workarounds for this issue.
References
Configurations
History
21 Nov 2024, 07:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/gookit/goutil/commit/d7b94fede71f018f129f7d21feb58c895d28dadc - Patch | |
References | () https://github.com/gookit/goutil/security/advisories/GHSA-fx2v-qfhr-4chv - Vendor Advisory | |
References | () https://security.netapp.com/advisory/ntap-20230427-0003/ - |
27 Apr 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 Mar 2023, 14:23
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:goutil_project:goutil:*:*:*:*:*:go:*:* |
14 Mar 2023, 18:35
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:goutil_project:gouitl:*:*:*:*:*:go:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | (MISC) https://github.com/gookit/goutil/security/advisories/GHSA-fx2v-qfhr-4chv - Vendor Advisory | |
References | (MISC) https://github.com/gookit/goutil/commit/d7b94fede71f018f129f7d21feb58c895d28dadc - Patch |
07 Mar 2023, 18:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-07 18:15
Updated : 2024-11-21 07:52
NVD link : CVE-2023-27475
Mitre link : CVE-2023-27475
CVE.ORG link : CVE-2023-27475
JSON object : View
Products Affected
goutil_project
- goutil
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')